Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0390 Information Disclosure in SAP Data Hub, SAP security note 2842034

SAP Note 2842034
SAP Security Note
Medium priority

SAP security note 2842034, "[CVE-2019-0390] Information Disclosure in SAP Data Hub", is a program error note released on November 12, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEIM-DH (Enterprise information management solutions > SAP Data Hub: Please use CA-DI instead.)
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released onNovember 12, 2019

Description

Symptom

Under certain conditions, SAP Data Hub allows an attacker to access information that would otherwise be restricted. Specifically, connections and their details maintained in Connection Manager are visible to users.

Solution

The policies “sap.dh.developer” and “sap.dh.metadata” should only be assigned in development systems. For productive usage, it is not recommended to assign these policies to users. Instead, connection access should be whitelisted by:

  • Creating a policy that provides access to a particular connection.
  • Assigning that policy to users who are allowed to access it.

To apply the workaround, update the installation of SAP Data Hub to version 2.7 or above.

Reason and prerequisites

Every user with the policy “sap.dh.connectionsAllRead” has access to all connections within the tenant. By default, these are users with the assigned policies “sap.dh.developer”, “sap.dh.metadata”, and “sap.dh.admin”.

CVSS

Score 5.0 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected components

  • DH_FOUNDATION: Version 2

Full note on SAP: SAP Support Launchpad note 2842034

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More